Описание
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
An information leak was discovered in postgresql. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat build of Quarkus | postgresql | Not affected | ||
Red Hat Decision Manager 7 | postgresql | Not affected | ||
Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
Red Hat Enterprise Linux 8 | libpq | Not affected | ||
Red Hat Enterprise Linux 8 | postgresql:10/postgresql | Not affected | ||
Red Hat Enterprise Linux 8 | postgresql:9.6/postgresql | Not affected | ||
Red Hat Enterprise Linux 9 | postgresql | Not affected | ||
Red Hat Fuse 7 | postgresql | Not affected | ||
Red Hat JBoss Enterprise Application Platform 6 | postgresql | Not affected |
Показывать по
Дополнительная информация
Статус:
3.1 Low
CVSS3
Связанные уязвимости
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
An information leak was discovered in postgresql in versions before 13 ...
3.1 Low
CVSS3